1,219 questions with Active Directory Federation Services tags
Configuring multiple UPN for ADFS SSO support with Office 365?
I've deployed ADFS 4.0 using Windows Server 2016 and OnPremise AD is synched using Azure AD Connect for the Hybrid configuration. Since our AD structure is Single Forest Single Domain AD and I can see the information like below from the Azure…
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
![](https://techprofile.blob.core.windows.net/images/kEaBzx2NUUuiIiWIzwa6Qw.png?8D9F54)
ADFS understanding needed
Hi All, I have been asked quite a few questions about our infrastructure and in particular ADFS (Active Directory Federation Services). I have no idea as I don't have anything to do with Federated Services. I don't even know if it is set up in our…
Federate from ADFS to Third Party Identity Provider
Have noticed that it is possible to federate from Azure AD to third party identity providers like Okta, Ping Identity via the Azure Portal (the customer does not want to use Azure AD) Is it possible to do the same via ADFS. Where when a client calls…
![](https://techprofile.blob.core.windows.net/images/GQWx4F-WakGnMqzQJ8Al7Q.png?8D82E3)
ADFS & HRD sign in page
Hello, We are facing an issue when applying HRD on lab & prod environement. We have 2 directories for authentication. We use ADFS installed on Windows Server 2019. We use OrganizationalSuffix (Set-AdfsLocalClaimsProviderTrust -TargetName…
ADFS 2.0 to 2016 migration - Service won't start after configuration import
Hello, I'm working on the migration of my ADFS 2.0 server (running 2008 R2) to ADFS 4.0 (on WS2016). All went fine during the ADFS 2016 farm installation, but as soon as I imported my 2.0 configuration, the ADFS service stopped and won't start. I'm…
ADFS - configuration to support Multi Forest environment.
Hello Friends, One our client is going to implement Cloud based SAP solution. Currently client is having 3 different Active Directory Forests and there is a trust between. The question is here, can we install one ADFS server and add and configure…
Steps / Procedures for configuring Office 365 with OnPremise ADFS 4.0 (2016) to allow SSO passwordless company-wide.
As I'm using Hybrid Office 365 and Exchange 2013 environment and the OnPremise AD is synced to Azure AD using Azure AD Connect. version 1.4.18.0 I have successfully configured and deployed multiple ADFS 4.0 (2016) in my corporate WAN environment. …
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
![](https://techprofile.blob.core.windows.net/images/kEaBzx2NUUuiIiWIzwa6Qw.png?8D9F54)
Steps and procedures when changing service account for ADFS and Azure AD Connect?
Hi Everyone, May I know what's the least amount of privilege for the Group Managed Service Accounts required for the ADFS v4.0 and Azure AD Connect ? Because at the moment the environment I'm managing is using Domain Administrator account, which…
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
![](https://techprofile.blob.core.windows.net/images/dy2uxuqmVUSxPXpdC94Arg.png?8DC877)
Upgrade the ADFS schema and Decommission the old 2012 R2 ADFS server
Hi All, I need some help in the steps and procedure for the existing ADFS v 3.0 (2012 R2) Migration to ADFS 4.0 (2016)? As at the moment, I have one ADFS farm called FS.domain.com: 1x old Windows Server 2012 R2 - PROD-ADFS01-VM (running as the…
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
![](https://techprofile.blob.core.windows.net/images/PT7QlfEdr0qdUKsDf1u5tw.png?8D801B)
Steps and procedure when upgrading ADFS to Windows Server 2016 with no outage?
Hi All, I wonder if anyone here can suggest the steps and procedure to perform an upgrade of current OnPremise Windows Server 2012 R2 ADFS server into Windows Server 2016. I have found this article for the upgrade:…
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
![](https://techprofile.blob.core.windows.net/images/WsWYoGdWukeBW66msAr6qQ.png?8D8128)
ADFS SingleLogoutService
Hello, We are having some issues with the SingleLogoutService. Where is the SingleLogoutService updated? This location points to a "page cannot be found" so we are trying to configure it. <SingleLogoutService…
![](https://techprofile.blob.core.windows.net/images/8d3870ddab9a429594c7132766a66e5d.png)
Bypass a HRD page using user login only and continue authentication on external provider. ADFS 2016\2019
I want to bypass HRD page on ADFS. Some of my RP already has parameter like login_hint for openID Connect and RedirectToIdentityProvider for WS Federation. But one RP should direct users to different external IPs depending on their login. We don't use…
ADFS 3.0 2012 R2 - I need help identifying my farm federation servers and if safe to remove old ones.
Hi I inherited our ADFS infrastructure with little documentation, and I am trying to identify how everything i working together. I have a document of the layout, so I know server named and purposes, but I immediately became confused, as the layout…
![](https://techprofile.blob.core.windows.net/images/8d3870ddab9a429594c7132766a66e5d.png)
E-mail claim not available from my external authentication method in AD FS 2016
I'm trying to plug a custom mfa provider to AD FS 2016, and while everything could work, I still have an issue when trying to specify which identity claim should be passed to my code. If in my dll I specify an Identity Claim with upn, it works: …
AD FS - Single Identifier with Multiple Endpoints - Index Selection in iDP Initiated Sign-On?
We have a requirement from a service provider to provide SSO for two separate parts of their web service - a user endpoint and an admin endpoint. We have a single RP identifier that applies to both so we have configured two endpoints with the respective…
Convert my federated identity to standard
I setup my tenant with a Lab for federation and now the lab server no longer exists. I need to change my tenant back to standard. I tried to follow this article. https://gallery.technet.microsoft.com/office/Convert-MsolDomain-To-ced5a502 Thanks
ADFS 2012R2 Claims that map from LDAP to SAML2 output not always clear
I'm trying to create a claim issuance policy. One of the mappings has to be the user SID. When I use the Get-ADUser powershell cmdlet I can see the User SID property is "SID", but when I try to find that in the list of pre-defined LDAP menu…
ADFS SSL Renewal
So I am very new to AD FS and have been dropped in it. I have an SSL Cert that is going to expire in 7 days time. The production System has 2 AD server with FS on and 2 Proxy Server. I have created a test plaform that mimics the production as best I can…
Features and packages in Windows server 2019
With the help of the dism command and the /Get-Features switch I got a list of features and packages that are enabled or disabled in my installation. Is there any link that explains what these features do? (e.g. feature name: Tpm-PSH-Cmdlets). I…
ADFS and MFA in Microsoft Browsers
Hi I'm after some help or suggestions as to what could be causing some odd behaviour in ADFS. A little background first. We have 2 WAP severs sitting in front of 2 ADFS servers which cal on 2 third party MFA severs, in our case Securenvoy. I'm using…
![](https://techprofile.blob.core.windows.net/images/8d3870ddab9a429594c7132766a66e5d.png)